Command Injection Vulnerability in MongoDB Extension for Visual Studio Code
CVE-2026-84967

5.1MEDIUM

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84967?

The MongoDB extension for Visual Studio Code has a vulnerability that stems from improper handling of special characters in user-supplied connection strings. This flaw allows an unauthenticated remote attacker to craft malicious input which, if accepted by a developer, results in unauthorized command execution within the extension’s integrated terminal. The attacker does not need privileges on the developer's machine; however, they must convince the developer to interact with the malicious input. Importantly, the terminal confirmation does not visually disclose the tampered text to the developer, increasing the risk of exploitation.

Affected Version(s)

MongoDB for VS Code 1.13.0 < 1.17.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.